October 5, 2026

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy’s Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization.

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy’s Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization.

IQVIA is a multinational company that provides healthcare data analysis, technology, and clinical research services. The company claims on its website that it operates in over 100 countries and handles 68 petabytes of data and 1.2 billion patient records.

Italian authorities investigated IQVIA’s data-processing practices in April 2025, and last month decided that the company did not provide adequate health-data anonymization warranties, despite its claims.

GPDP has found that IQVIA’s Italian division had created a database containing the health information of roughly one million patients by aggregating data from 800 general practitioners.

While the company used a unique code instead of patients’ names in those records, the data protection agency found they could be used to track and de-anonymize patients over time.

“The code associated with each patient made it possible to track them over time,” explained GPDP in an announcement published late last week.

“Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them.”

In addition, IQVIA processed data without an appropriate legal basis and without informing patients, which violates the GDPR (General Data Protection Regulation).

Finally, IQVIA allegedly did not establish or follow any data retention periods, with the GPDP finding records dating back as far as 2001.

For a subset of 3,300 patients in IQVIA’s database, the company also included names, tax identification numbers, addresses, and contact details.

In addition to the $7.8 million fine, Italian authorities also ordered the company to bring its practices into compliance within 120 days.

BleepingComputer has contacted the firm with questions about the fine, and a spokesperson sent us the following statement:

“IQVIA is committed to the responsible use of data and information and continues to cooperate with the Authority. Protecting data is a core priority for IQVIA, and we maintain robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare.

IQVIA acknowledges the decision adopted by the Italian Data Protection Authority and reserves the right to appeal. The dataset to which the Italian Data Protection Authority’s decision relates is not used by IQVIA in conduct of clinical research services and does not relate to the conduct of clinical trials on behalf of the sponsors.

We have engaged constructively with the Italian Data Protection Authority throughout this process and have already taken steps to adopt the measures necessary to ensure full alignment with the Authority’s guidance.”

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Originally published on BleepingComputer